Back to the show

AI & Tech Daily

Cyber Models Move Behind Gates as Platforms Expose Only Part of the Machine

18:12

OpenAI’s GPT-5.6-Cyber arrives through tightly controlled Daybreak access, promising faster vulnerability research while putting model vendors in charge of who gets the strongest capabilities. Z.ai pauses the open-weight release of GLM-5.3 after reporting potent cyber performance. We also examine allegations that Grok enabled the mass creation of abusive images from a childhood photo, AMD’s prospective compute support for Britain’s BOLD research lab, a Klaviyo tracker error that exposed signup passwords, and FDA clearance for Samsung’s hearing-aid software. In What Changes for You: X reveals more of its ranking and visibility systems, while ChatGPT Ads expands to five more countries.

Full transcript

Read the episode.

I'm Jesse Owen. This is AI and Tech Daily.

OpenAI Puts Its Strongest Cyber Model Behind Daybreak

A model that can validate exploits may help defenders close the window on an attack. Give it the wrong access, though, and the same capability can widen that window fast.

That tension is why OpenAI’s new cyber release is the development worth spending time on. On August 10, the company launched GPT-5.6-Cyber through Daybreak Red, its controlled access tier for specialised vulnerability research, exploit validation and security testing. This isn’t a general ChatGPT release, and OpenAI isn’t offering unrestricted model access. Applicants face approval, identity controls, monitoring and attestations that their work is authorised. Individual Daybreak users also have to use hardware security keys from September 1.

There are now two Daybreak tiers. Blue provides GPT-5.6 Sol with safeguards tailored to authorised defensive work. Red provides the more specialised cyber model for work where standard safety restrictions could obstruct legitimate testing. OpenAI has also expanded Daybreak through security-service partners, while retaining control over which partners receive the underlying model. And from August 11, approved customers could access both tiers through Amazon Bedrock, provided they were already enrolled in Daybreak. That AWS route matters operationally because a security team may be able to place the model inside governance and procurement arrangements it already uses. It doesn’t remove OpenAI’s gate.

The performance claim is striking, but it needs the right label. OpenAI says GPT-5.6-Cyber completed 95 per cent of requests in its internal Advanced Cybersecurity Completion Rate evaluation, compared with 1.5 per cent for standard GPT-5.6 Sol. That’s a company-designed test, not independent validation. OpenAI also says the model found two previously unknown vulnerabilities in Google’s V8 JavaScript engine that could be chained to escape the heap sandbox. Google fixed one as CVE-2026-15903. Several other claimed discoveries are still under coordinated disclosure, which means the public can’t yet assess the full record.

For approved defenders, the immediate gain could be shorter investigation and response cycles. A model allowed to reason through exploit behaviour may help reproduce a flaw, validate whether a patch works, or prioritise a real exposure more quickly than a broadly available assistant. But the burden shifts to the customer as well. OpenAI says consequential actions need supervision, and teams need to isolate the model from production systems. A capable cyber agent connected carelessly to live infrastructure is not simply another productivity tool.

In practice, that makes deployment architecture part of the safety case. A team can gain less-restricted reasoning without giving the model standing credentials, unrestricted network access or authority to act on findings. The access review happens once, but containment has to work on every task. Bedrock may simplify identity and logging for an AWS customer; it cannot decide whether a generated exploit should touch a live system.

My read is that controlled distribution could genuinely compress defensive response time, while also concentrating a lot of judgment in the vendor. OpenAI decides who qualifies, monitors use and defines the boundaries of acceptable work. Customers then inherit a serious containment problem once access is granted. The missing piece is independent evidence: OpenAI hasn’t yet published the promised GPT-5.6-Cyber system card, and we still have limited information about real-world error, misuse and containment rates. The launch establishes a powerful new security capability. It doesn’t yet establish how reliably that capability stays inside the lines drawn around it.

Z.ai Pauses an Irreversible Release

OpenAI can keep its strongest model behind an approval gate. The control problem sharpens when the weights are meant to leave the lab entirely.

According to Axios, Chinese AI company Z.ai announced GLM-5.3 on August 14, then delayed publication of its model weights for two weeks while it tested and strengthened safety controls. Model weights are the learned parameters that make the system work. Once they’re downloadable, developers can run the model locally, modify it and deploy it without the original provider remaining in the loop. Z.ai has acknowledged that it won’t control modification or use after release.

The company reports an 84.5 per cent result on CyberGym, a benchmark that tests whether models can reproduce known software vulnerabilities. It also claims that its GLM models have found more than 2,400 vulnerabilities, including more than 1,000 rated critical or high. Those figures sound formidable, but they remain company claims. The reported comparison with leading US models hasn’t been independently validated, and a benchmark based on known vulnerabilities doesn’t tell us everything about performance against unfamiliar systems in messy real environments.

Even so, the choice to pause is revealing. Z.ai appears to accept that cyber capability changes the risk calculation for an open-weight release. The difficult part is that two more weeks of testing can improve defaults, documentation or built-in controls, but those protections may be altered once the weights are in other hands. A delay is useful only if the work done during it meaningfully reduces predictable harm or changes the terms of release. Time by itself isn’t a safeguard.

Developers waiting for GLM-5.3 now have a short delay rather than access, while security organisations have a brief preparation window. They can assess where a locally deployable cyber model could affect threat monitoring, vulnerability triage and internal controls. My assessment is that Z.ai has recognised the right problem but chosen a temporary control for an irreversible step. The final release date could still move, and the effectiveness of the added safety work is unknown. Once the weights are public, the strongest remaining protections will sit with the people operating the model and the systems exposed to it.

A Grok Lawsuit Tests Image-Safety Claims

The next case is much more personal, and the facts are allegations rather than findings by a court.

A woman identified as Jane Doe 4 has joined a pending lawsuit against xAI, alleging that her stepfather used Grok to transform a childhood photograph of her into more than 7,000 explicit images. The report was published on August 15. She joined a case initially brought by three Tennessee teenagers, who accuse xAI of failing to put basic protections in place against generating explicit imagery of real people and minors.

The plaintiffs are seeking class-action status. No court has determined that xAI is liable, and no class has been approved. TechCrunch reported that xAI hadn’t responded by the time its story was published. Those limits matter: the allegation is grave, but it remains unproven litigation rather than an established account of product behaviour and responsibility.

The scale alleged here still exposes the central safety question for image transformation. A tool doesn’t need to create a new identity from scratch to cause severe harm. If it can take an identifiable person’s photograph and rapidly produce abusive variations, cheap generation turns one source image into an industrial quantity of material. When the source depicts a child, consent checks and minor protections are not edge-case features. They are part of the core product boundary.

Providers have to think beyond whether a single prompt contains a prohibited phrase. Repeated generation, use of a real person’s image, indicators that the subject is a minor, and attempts to work around refusals can all be relevant signals for abuse monitoring. That observation doesn’t prove what Grok detected or failed to detect in this alleged case; the briefing provides no such technical record. It does show why evaluating safeguards only one output at a time can miss the cumulative harm enabled by scale.

For the public, my conclusion is blunt: easy image editing carries a severe external cost when the person pictured has no practical way to consent, monitor or stop the output. This case will add legal and reputational pressure on generative-image companies to demonstrate that protection for real people, especially children, is built into deployment rather than added after abuse becomes visible.

AMD Backs Britain’s BOLD Research Lab

From platform harm, there’s a quieter story about who gets the compute needed to explore alternatives.

AMD has signed a memorandum of understanding to provide up to five million pounds in compute resources during the first 18 months of Britain’s Open-ended Learning and Discovery Lab, known as BOLD. The proposed lab brings together researchers from Oxford, University College London and Imperial College London. Its prospective work spans alternatives to backpropagation, human-centred multi-agent discovery and embodied AI.

Backpropagation is the dominant method used to adjust modern neural networks during training. Research into alternatives is a long-horizon bet: it could produce more efficient or biologically plausible learning methods, or it could yield no replacement that works at useful scale. Embodied AI examines systems acting through robots or other physical interfaces, while multi-agent discovery studies how several AI systems might work together, with people, on research problems. None of that amounts to a product announcement or a public model arriving now.

The commitment also needs careful wording. It’s planned support under a memorandum, not a completed grant. AMD and the lab haven’t disclosed the precise hardware allocation or delivery timetable, and the final value delivered may be less than the headline ceiling. Compute resources can also include access arrangements and software expertise rather than a simple transfer of chips.

Still, academic teams often struggle to obtain accelerator capacity at the level needed for ambitious experiments. If the agreement is fulfilled, BOLD gets another route to both compute and AMD’s software ecosystem, reducing some dependence on the small group of commercial labs that can fund frontier work internally. It also gives AMD a chance to place its tools with researchers developing unfamiliar training methods and workloads.

My take for research organisations is cautiously positive. Industry-backed academic compute can broaden the set of institutions able to test unconventional ideas, and openness in the resulting research could spread the benefit. But up to five million pounds over 18 months is modest beside commercial frontier-training budgets, and a memorandum is still contingent. The useful measure won’t be the pledge alone. It’ll be the hardware and access actually delivered, the work researchers can publish, and whether the collaboration leaves the academic agenda genuinely open.

A Marketing Tracker Became a Password Leak

Here’s a security failure with a very ordinary cause: code meant to measure customers saw data it never needed.

Newly disclosed research found that Klaviyo’s signup form sent information entered by customers, including passwords, to third-party advertising and technology trackers. The exposed fields reportedly also included email addresses, company names, websites and phone numbers. Researchers observed the misconfiguration from at least February 2024 through November 2025, and Klaviyo says it has fixed the issue.

Klaviyo says fewer than 200 people are known to have been affected, based on the active logs available to it. That figure can’t safely be read as a complete historical total. The company didn’t disclose how long it retains logs, while the observed configuration spanned well over a year. It’s also unknown which third parties retained the information or whether any exposed credentials were misused.

The mechanism is important because it’s so mundane. Marketing and analytics scripts often listen for page events and form interactions. If they’re configured too broadly, or loaded on registration and authentication pages without strict field controls, they can turn a routine conversion measurement into data exfiltration. The password may still be encrypted correctly when stored by the service, yet leak before submission because another script reads the form in the browser. Strong database hashing doesn’t solve that path.

For anyone notified, the practical response is to replace the exposed password and change it anywhere else it was reused. The organisational lesson reaches beyond Klaviyo. Registration, login and password-reset pages deserve an inventory of every third-party script, the fields each script can observe, and tests that verify sensitive values never enter analytics events. Content security controls can help limit where data is sent, but configuration and tag-manager changes need review as part of the security boundary too.

My judgment is that marketing pixels now belong in the same threat model as other code handling credentials. They may arrive through a different team and promise business insight rather than authentication, but the browser doesn’t respect that organisational distinction. A small analytics mistake can quietly bypass otherwise sound account security.

Galaxy Buds Gain a Regulated Hearing Mode

A pair of consumer earbuds is also edging into regulated health technology, though the feature isn’t available yet.

Samsung announced on August 11 that the US Food and Drug Administration had cleared software allowing compatible Galaxy Buds to function as an over-the-counter hearing aid. It’s intended for adults aged 18 or older who perceive mild-to-moderate hearing loss. The feature combines a self-administered hearing test with personalised amplification, using the result to adjust sound for the wearer.

Samsung plans to make it available on the Galaxy Buds3 Pro and Buds4 Pro in the United States and selected approved markets during the fourth quarter of 2026. A compatible Galaxy device is required. So this is regulatory clearance and a launch plan, not something every Buds owner can switch on immediately. Samsung also hasn’t named every market in the rollout.

The attraction is straightforward. People who already use compatible earbuds may be able to access hearing assistance through familiar hardware, without buying a separate device at the outset. Over-the-counter status can lower some practical barriers for adults whose hearing difficulty falls within the intended range. Personalised amplification is more useful than simply making every sound louder, because hearing loss can affect frequencies differently.

There are boundaries worth keeping in view. The clearance covers perceived mild-to-moderate loss in adults, and real-world performance across different hearing conditions hasn’t yet been established independently in the material we have. Severe, sudden, one-sided or uncertain symptoms can still call for professional assessment. Regional approvals also determine where Samsung can enable the software, and requiring a Galaxy phone plus one of two earbud models creates clear ecosystem lock-in.

For the general public, I see this as a meaningful accessibility gain rather than a replacement for audiology. Regulated software can bring assistance into hardware people are comfortable wearing, which may make early support easier to try. The limitation is that the benefit arrives later in 2026, only in approved markets and only for users inside Samsung’s compatible device chain.

What Changes for You

Two platform changes now give users more to inspect, while also asking them to trust what remains out of view.

X expanded the public repository for its For You recommendation system on August 13. Under an Apache 2.0 licence, it now includes production-oriented ranking configuration, documented ranking weights, Phoenix training code, synthetic training data and visibility-filtering systems. Researchers and developers can inspect more of how ranking, model training and moderation fit together.

A pilot called Under the Hood gives participating users aggregate visibility-impacting labels applied to their accounts and posts. That may help somebody investigate why distribution appears limited. It’s useful, but incomplete: X withholds some Grok prompts and moderation rules to reduce gaming, parts of the deployment infrastructure are absent, and the reports don’t explain every individual decision. X also hasn’t provided independent assurance that published defaults always match production. My read is that code plus visible outcomes improves transparency, while stopping short of a full audit trail.

ChatGPT Ads also expanded on August 11, reaching eligible adults on the Free and Go tiers in the United Kingdom, Mexico, Brazil, Japan and South Korea. Plus, Pro, Business, Enterprise and Education remain ad-free. OpenAI says ads are labelled and separated from answers, advertisers can’t access chats, and minors and sensitive topics are excluded.

For affected users, ad matching can use the current conversation topic, past chats and previous ad interactions. Free users can opt out, but they’ll receive fewer daily messages; the alternatives include accepting the ads or paying for an ad-free tier. Advertising may subsidise free access, but conversational history introduces a trust and privacy trade-off even if advertisers never receive the chats. OpenAI’s privacy and answer-independence claims haven’t been independently tested here, so the practical limit is how much contextual matching you’re comfortable allowing in return for access.

You'll find the sources and full transcript at owenonthenet.com. Thanks for listening.

Sources

Reporting behind this episode.

  1. openai.com/index/expanding-daybreak-as-the-cyber-defense-window-narrows
  2. axios.com/2026/08/14/china-open-source-ai-glm-53
  3. techcrunch.com/2026/08/15/woman-claims-her-stepfather-used-grok-to-transform-childhood-photo-into-explicit-imagery
  4. itpro.com/infrastructure/amd-pledges-support-for-oxford-frontier-ai-research-lab
  5. techcrunch.com/2026/08/10/signed-up-for-klaviyo-dozens-of-advertisers-may-have-seen-your-password
  6. news.samsung.com/global/samsungs-hearing-aid-feature-on-galaxy-buds-cleared-by-fda
  7. github.com/xai-org/x-algorithm
  8. openai.com/index/testing-ads-in-chatgpt